Australia Cyber Security ActFree Resource

Australia Cyber Security Act Smart Device and Ransomware Reporting Hub

Use this hub to separate the Cyber Security Act 2024's four main pathways: consumer smart-device duties, reporting, voluntary coordination of significant incidents, and Cyber Incident Review Board reviews.

By Sorena AIBased on official Australian sourcesNo signup required
Quick scan
Artifact
Commencement view
Part 3 ransomware reporting and Part 5 provisions commenced on 29 May 2025, Part 2 smart-device provisions commenced on 29 November 2025, and the Smart Devices Rules' operative standards commenced on 4 March 2026.
Product and reporting scope
Separate consumer grade checks from ransomware reporting business entity checks and overlap questions.
Evidence and topic guides
Use focused guides for smart device standards, statements of compliance, reports, deadlines, penalties, templates, and cross-market comparisons.

This hub is the starting point for Australia Cyber Security Act 2024 product release checks, incident reporting preparation, overlap triage, and evidence planning.

Key dates
2024
Act
$3m
Threshold
72h
Report
CIRB
Reviews
What you can decide faster
Smart devices
Check connectivity, intended or likely household use, Australian consumer acquisition, the six product exclusions, and whether you act as manufacturer or supplier before applying the password, security-issue reporting, support-period, and statement duties. The Australian Consumer Law test can cover a business acquisition, including goods priced at no more than the prescribed $100,000 amount, but excludes goods acquired for resale or for specified production, manufacture, repair, or treatment uses. The statement is a retained regulatory record and need not be physically provided at the point of sale.
Ransomware reporting
Check whether the entity is responsible for a critical-infrastructure asset covered by Part 2B of the Security of Critical Infrastructure Act 2018, the mandatory cyber incident notification regime for specified assets, or carries on business in Australia above the $3 million previous-year turnover threshold. The turnover limb excludes Commonwealth and State bodies and responsible entities for critical-infrastructure assets. Section 26 says turnover must exceed the threshold. The current government form says "equal to or exceeds $3 million," so an entity at exactly $3 million should confirm the filing position promptly. If the remaining incident, demand, and payment conditions are met, the report is due within 72 hours of the payment or awareness trigger.
Incident review readiness
Understand how reviews focus on learning from certain cyber security incidents, public reporting, sensitive information redaction, and non-interference with investigations or proceedings.
Smart devices
Ransomware reports
CIRB reviews
Publication details
Editorial metadata for this artifact
Author
Sorena AI
Published
Mar 4, 2026
Updated
Jul 16, 2026

Start with the product, entity, payment, or incident in front of you. For ransomware reporting, check whether the entity was impacted by a cyber security incident, received a demand, and made a to the extorting entity or learned that another entity made one on its behalf. The guides identify the legal role, trigger, applicable date, required record, and any separate Security of Critical Infrastructure Act check.

Timeline

Key milestones for Australia Cyber Security Act

Use cited milestones to sequence smart device release controls, reporting readiness, and review awareness.

Loading timeline...
Recommended reading path

Choose the next Cyber Security Act decision

New to the Act? Establish the applicable pathway and legal role first. If scope is already documented, jump to the product control, payment-reporting workflow, evidence pack, deadline, enforcement question, or comparison you need.

1

Start here: pathway, scope, and roles

Separate smart-device, ransomware, incident-coordination, CIRB, and SOCI questions before assigning obligations. Then document the product, entity, legal role, and trigger.

2

Obligations and controls

Apply the current product-security controls, ransomware payment-reporting trigger, legal requirements, and enforcement consequences only after the relevant pathway is established.

3

Implementation and evidence

Turn the applicable obligations into release gates, statements of compliance, retained technical records, response playbooks, owners, and reusable evidence.

Australia Cyber Security Act Compliance Guide
A cited compliance guide for Australia Cyber Security Act smart-device statements, ransomware payment reporting, incident coordination, and review-board readiness.
Read guide
Australia Cyber Security Act Compliance Checklist
Concrete checklist items for Australian Cyber Security Act smart-device and ransomware duties, with SOCI and APRA CPS 234 evidence checks.
Read guide
Cyber Security Act 2024 Smart Device Compliance Checklist
Checklist for Australia Cyber Security Act 2024 smart-device scope, password controls, vulnerability reporting, security-update support periods, statements of compliance, retention, and evidence.
Read guide
Australia Smart Device Compliance Statement
What a smart-device statement of compliance must contain under Australia's Cyber Security Act 2024 and Smart Devices Rules, who prepares and supplies it, how long to retain it, and how to prepare for examination.
Read guide
Australia Cyber Security Act Statement of Compliance Evidence
Evidence guide for Australia Cyber Security Act smart-device statements of compliance: required fields, manufacturer and supplier records, five-year retention, and examination readiness.
Read guide
Australia Compliance Statement Evidence Workflow
Evidence workflow for preparing, supplying, and retaining statements of compliance under Australia's Cyber Security Act 2024 and Smart Devices Rules.
Read guide
Australia Cyber Security Act templates
Source-backed field lists for Australia Cyber Security Act smart-device scope, statements of compliance, ransomware reports, notices, SOCI overlap, and records.
Read guide
5

Compare markets or answer a focused question

Keep Australian evidence distinct when comparing the EU CRA or UK PSTI regime, or go directly to the FAQ when a product, reporting, recordkeeping, or notice question is already known.

Next step

Turn Australia Cyber Security Act guidance into owned implementation work

Route product, incident response, legal, and security actions into accountable work. Assessment Autopilot can convert the guidance into owners and evidence requests; Research Copilot can support cited scope or interpretation questions.

What this unlocks
  • Start with a product, entity, payment event, or incident-review question and route it to the right owner.
  • Use Assessment Autopilot to request statement-of-compliance evidence, support period records, reporting playbooks, and review checkpoints.
  • Use Research Copilot for cited questions about product scope, reporting business entity status, overlap, or procedure.
  • Keep legal interpretation, engineering evidence, and incident reporting records connected to the same cited guidance.
Australia Cyber Security Act artifact preview
Share it internally
Download the timeline export to align legal, product, engineering, and commercial teams on milestones and deadlines.